Evidence hierarchy
WAFWiki prioritizes official documentation, product pages, public repositories, release notes, pricing pages, and reproducible hands-on notes. Vendor claims are treated as claims until they are checked against documentation or test evidence.
Hands-on status
Pages may include different evidence levels: source-only research, lab validation, or production case notes. When a page is not based on a completed lab test, it should be written as an evaluation guide instead of a benchmark result.
No paid ranking
Commercial relationships, affiliate links, or vendor relationships must not determine verdicts, shortlist order, or comparison conclusions. Any paid or affiliate relationship must use rel="sponsored nofollow" where applicable and be labeled separately from editorial analysis.
Advertising and monetization
WAFWiki may display clearly identifiable advertising or use affiliate links to support free access to the site. Ads must not be styled as navigation, download actions, editorial recommendations, or research conclusions. Advertising partners cannot review, approve, or suppress independent editorial findings.
Defensive security scope
WAFWiki publishes defensive Web Application Firewall research. Commands, payloads, and traffic examples must be limited to authorized labs, controlled demonstrations, or validation guidance. The site does not promote unauthorized access, malware, credential theft, service disruption, or bypassing access controls.
Update cadence
Vendor data cards include a last-checked field. High-traffic pages and pricing-sensitive pages should be reviewed first, followed by comparison, tutorial, and glossary pages. Material vendor changes should trigger an earlier review.
Corrections
If a factual issue is reported, WAFWiki should verify it against the source hierarchy, update the affected page, and preserve the editorial distinction between documented facts, test observations, and opinionated recommendations. Corrections and policy questions can be submitted through the contact page.